Impersonation Vulnerability in FreshRSS Self-Hosted Feed Aggregator
CVE-2025-46341
7.1HIGH
What is CVE-2025-46341?
FreshRSS, a self-hosted RSS feed aggregator, is susceptible to a user impersonation vulnerability when utilizing HTTP authentication through a reverse proxy. Attackers can deceive the system into believing they are another user by manipulating the Remote-User
or X-WebAuth-User
headers during crafted requests. To exploit this issue, they need prior knowledge of the FreshRSS instance’s IP address, the admin's username, and must possess an account on the system. This vulnerability facilitates unauthorized access to internal services and may enable privilege escalation under certain configurations. FreshRSS version 1.26.2 addresses this flaw, highlighting the importance of prompt updates to safeguard user accounts.
Affected Version(s)
FreshRSS < 1.26.2